VulnerabilityBleeping Computer
6.0 — HIGH
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Hackers are exploiting a medium-severity vulnerability in the Gravity SMTP WordPress plugin, allowing them to steal email service credentials and gain detailed information about the site's software stack.
⚙️Technical Details
Affected Systems
Gravity SMTP WordPress plugin
Attack Vectors
/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
💥Impact Assessment
Severity: medium
Who Is at Risk
WordPress site administrators and users with email service credentials exposed through the Gravity SMTP plugin
🛡️Recommended Actions
1Update the Gravity SMTP WordPress plugin to version 2.1.5 or later
2Block requests to '/wp-json/gravitysmtp/v1/tests/mock-data' in web server access logs
3Monitor for suspicious activity and implement additional security measures
📦Affected Products
Gravity SMTP WordPress plugin
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
